First published: Thu Jun 10 2021(Updated: )
An issue was discovered in JerryScript 2.4.0. There is a heap-buffer-overflow in lexer_parse_number in js-lexer.c file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jerryscript Jerryscript | =2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26195 is classified as a high severity vulnerability due to its potential for exploitation via heap-buffer-overflow.
To fix CVE-2021-26195, upgrade to the latest version of JerryScript where this vulnerability is patched.
CVE-2021-26195 affects JerryScript version 2.4.0.
CVE-2021-26195 impacts the lexer_parse_number function within the js-lexer.c file.
Yes, CVE-2021-26195 may be exploited remotely by attackers who can send specially crafted inputs.